IntesyncCVEs & Vulnerabilities

13 CVEs affecting Intesync products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

solismed 9miniweb 4
CVE-2019-17428MEDIUM

An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.

12 Dec 2019
5.9
CVSS
CVE-2019-16246CRITICAL

Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.

12 Dec 2019
9.8
CVSS
CVE-2019-15936CRITICAL

Intesync Solismed 3.3sp allows Insecure File Upload.

12 Dec 2019
9.8
CVSS
CVE-2019-15935MEDIUM

Intesync Solismed 3.3sp has XSS.

12 Dec 2019
6.1
CVSS
CVE-2019-15934HIGH

Intesync Solismed 3.3sp has CSRF.

12 Dec 2019
8.8
CVSS
CVE-2019-15933CRITICAL

Intesync Solismed 3.3sp has SQL Injection.

12 Dec 2019
9.8
CVSS
CVE-2019-15932CRITICAL

Intesync Solismed 3.3sp has Incorrect Access Control.

12 Dec 2019
9.8
CVSS
CVE-2019-15931CRITICAL

Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.

12 Dec 2019
9.8
CVSS
CVE-2019-15930MEDIUM

Intesync Solismed 3.3sp allows Clickjacking.

12 Dec 2019
4.3
CVSS
CVE-2009-4552MEDIUMpoc

Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

4 Jan 2010
4.3
CVSS
CVE-2009-4551HIGHpoc

SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php.

4 Jan 2010
7.5
CVSS
CVE-2009-3420MEDIUMpoc

Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO.

26 Sep 2009
4.3
CVSS
CVE-2009-3419HIGHpoc

SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter.

26 Sep 2009
7.5
CVSS
← PrevPage 1 / 1Next →
Intesync CVEs & Vulnerabilities — 13 Tracked